Oracle Begins Their Monthly Critical Security Patch Updates with Multiple Critical CVEs

Last Updated: Monday, June 1, 2026 2:39 PM

What’s Happening

Oracle has begun releasing Critical Security Patch Updates (CSPU). They released the first on Thursday, May 28th, 2026. They have outlined a subsequent monthly schedule as follows:

  • 16 June 2026
  • 18 August 2026
  • 15 September 2026
  • 17 November 2026

The CVE list from Oracle’s May 28th Critical Security Patch Update includes several high severity vulnerabilities. It is not yet known if they are EITW. We strongly recommend identifying any Oracle products in your network and patching them ASAP. The following are the Risk Matrices, split up by product, provided by Oracle in their CSPU.

Oracle Database Server Vulnerabilities:

CVE ID Component Package and/or Privilege Required Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req’d
User
Interact
Scope Confid-
entiality
Inte-
grity
CVE-2026-46833 Net Service None TLS Yes 9.0 Network High None None Changed High High High 23.4.0-23.26.2 See Note 1
CVE-2026-46834 Net Service None TLS Yes 7.5 Network Low None None Un-
changed
None None High 23.4.0-23.26.2 See Note 1
CVE-2026-46835 Net Service None TLS Yes 7.5 Network Low None None Un-
changed
None None High 23.4.0-23.26.2 See Note 1

The Net Service vulnerabilities can effect Oracle Homes, Oracle Database, Oracle Grid, and Oracle Client.

Oracle REST Data Services Vulnerabilities:

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req’d
User
Interact
Scope Confid-
entiality
Inte-
grity
CVE-2026-46840 Oracle REST Data Services Backend-as-a-Service HTTPS Yes 10.0 Network Low None None Changed High High High 24.2.0-26.1.0
CVE-2026-46775 Oracle REST Data Services Core HTTPS No 9.9 Network Low Low None Changed High High High 24.2.0-26.1.0
CVE-2026-46839 Oracle REST Data Services Core HTTPS No 9.9 Network Low Low None Changed High High High 24.2.0-26.1.0
CVE-2026-2332 Oracle REST Data Services Core (Eclipse Jetty) HTTPS Yes 9.1 Network Low None None Un-
changed
High High None 24.2.0-26.1.0
CVE-2026-35277 Oracle REST Data Services Core HTTPS No 8.1 Network Low Low None Un-
changed
High High None 24.2.0-26.1.0
CVE-2026-35266 Oracle REST Data Services Core HTTPS No 7.9 Network High Low Required Changed High High Low 24.2.0-26.1.0
CVE-2026-46829 Oracle REST Data Services Mongoapi HTTPS Yes 7.5 Network Low None None Un-
changed
None None High 24.2.0-26.1.0
CVE-2026-46842 Oracle REST Data Services Core HTTPS Yes 5.3 Network Low None None Un-
changed
None Low None 24.2.0-26.1.0
CVE-2026-46843 Oracle REST Data Services Core HTTPS Yes 5.3 Network Low None None Un-
changed
None None Low 24.2.0-26.1.0
CVE-2026-46841 Oracle REST Data Services General HTTPS Yes 5.3 Network Low None None Un-
changed
Low None None 24.2.0-26.1.0
CVE-2026-46830 Oracle REST Data Services Mongoapi HTTPS Yes 5.3 Network Low None None Un-
changed
Low None None 24.2.0-26.1.0
  • The patch for CVE-2026-2332 also addresses CVE-2026-5795.

Additional patches included for non-exploitable CVEs:

  • Oracle REST Data Services
    • Core (Lodash): CVE-2026-4800, CVE-2025-13465 and CVE-2026-2950 [VEX Justification: vulnerable_code_not_in_execute_path].

Oracle Communications Vulnerabilities:

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req’d
User
Interact
Scope Confid-
entiality
Inte-
grity
CVE-2026-33557 Oracle Communications Unified Assurance Message Bus (Apache Kafka) TCP Yes 9.1 Network Low None None Un-
changed
High High None 6.1.1-7.0.0
CVE-2025-15467 Oracle Communications Unified Assurance Core (MySQL Server) HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 6.1.1-7.0.0
CVE-2026-41044 Oracle Communications Unified Assurance Message Bus (Apache ActiveMQ) HTTP No 8.8 Network Low Low None Un-
changed
High High High 6.1.1-7.0.0
CVE-2025-58050 Oracle Communications Unified Assurance Core (PCRE2) HTTP No 8.1 Network Low Low None Un-
changed
High None High 6.1.1-7.0.0
CVE-2026-34487 Oracle Communications Unified Assurance Core (Apache Tomcat) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 6.1.1-7.0.0
CVE-2026-24308 Oracle Communications Unified Assurance Core (Apache ZooKeeper) TCP Yes 7.5 Network Low None None Un-
changed
High None None 6.1.1-7.0.0
CVE-2026-25646 Oracle Communications Unified Assurance Core (libpng) HTTP No 6.4 Network High High Required Un-
changed
High High High 6.1.1-7.0.0
CVE-2026-34059 Oracle Communications Unified Assurance Core (Apache HTTP Server) HTTP No 4.5 Network Low High Required Un-
changed
High None None 6.1.1-7.0.0
  • The patch for CVE-2026-41044 also addresses CVE-2026-40466 and CVE-2026-41043.
  • The patch for CVE-2025-15467 also addresses CVE-2025-14017, CVE-2026-21998, CVE-2026-22001, CVE-2026-22002, CVE-2026-22004, CVE-2026-22005, CVE-2026-22009, CVE-2026-22015, CVE-2026-22017, CVE-2026-34270, CVE-2026-34271, CVE-2026-34276, CVE-2026-34303, CVE-2026-34304, CVE-2026-34308, CVE-2026-35236, CVE-2026-35237, CVE-2026-35238, CVE-2026-35239, and CVE-2026-35240.
  • The patch for CVE-2026-33557 also addresses CVE-2026-35554.
  • The patch for CVE-2026-34059 also addresses CVE-2026-23918, CVE-2026-24072, CVE-2026-28780, CVE-2026-29168, CVE-2026-29169, CVE-2026-33006, CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, and CVE-2026-34032.
  • The patch for CVE-2026-24308 also addresses CVE-2026-24281.
  • The patch for CVE-2026-34487 also addresses CVE-2026-29145, CVE-2026-34483, CVE-2026-34486, and CVE-2026-34500.

Oracle E-Business Suite Vulnerabilities:

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req’d
User
Interact
Scope Confid-
entiality
Inte-
grity
CVE-2026-46822 Oracle iAssets Internal Operations HTTP No 9.9 Network Low Low None Changed High High High 12.2.3-12.2.15
CVE-2026-46824 Oracle Universal Work Queue Work Provider Site Level Administration HTTP No 9.9 Network Low Low None Changed High High High 12.2.3-12.2.15
CVE-2026-46817 Oracle Payments File Transmission HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.3-12.2.15
CVE-2026-46819 Oracle Internet Procurement Connector Internal Operations HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.3-12.2.15
CVE-2026-46837 Oracle Flow Manufacturing Security SQL No 8.8 Network Low Low None Un-
changed
High High High 12.2.9-12.2.15
CVE-2026-46827 Oracle Payroll Self Service Manager HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15
CVE-2026-46826 Oracle Payroll Internal Operations HTTPS No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15
CVE-2026-46820 Oracle Financials Common Modules Common Components HTTP No 8.5 Network Low Low None Changed High Low None 12.2.3-12.2.15
CVE-2026-46828 Oracle Payroll Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15
CVE-2026-46821 Oracle Financials Common Modules Common Components HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15
CVE-2026-46823 Oracle Public Sector Financials (International) Authorization HTTPS No 7.7 Network Low Low None Changed High None None 12.2.6-12.2.15
CVE-2026-46818 Oracle Payments File Transmission HTTPS Yes 7.4 Network High None None Un-
changed
High High None 12.2.3-12.2.15

Oracle Hospitality Vulnerabilities:

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req’d
User
Interact
Scope Confid-
entiality
Inte-
grity
CVE-2026-34311 Oracle Hospitality OPERA 5 Property Services Opera HTTP Yes 9.8 Network Low None None Un-
changed
High High High 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6, 5.6.28

The May 28th 2026 Oracle Critical Security Patch Update Advisory:

https://www.oracle.com/security-alerts/cspumay2026.html

Actions

Identify any Oracle products in your network. Patch them immediately.

Notes

A matrix with more granular detail provided by Oracle

https://www.oracle.com/security-alerts/cspumay2026verbose.html

Oracle’s announcements that they are beginning a monthly patch schedule:

https://www.oracle.com/security-alerts/

https://blogs.oracle.com/security/update-monthly-critical-security-patch-updates-cspus-begin-may-28-2026